πŸ‘‹ Hello, I'm
Portrait of Victor Muthomi

Victor Muthomi

Software Engineer | Intelligent Systems, Pentester & Scalable Platforms

Building secure, scalable solutions across ERP systems, mobile applications, AI/ML integration, and penetration testing

Accomplished software engineer specialising in full-stack development using Python, FastAPI, Flask, Flutter, and the Frappe/ERPNext ecosystem. Experienced in designing intelligent, data-driven systems by integrating machine learning models, data pipelines, secure APIs, and automation workflows into production applications. I also bring hands-on penetration testing knowledge across reconnaissance, vulnerability assessment, web/API security, controlled exploitation, Linux security, and professional reporting. Passionate about advancing the intersection of software engineering, AI/ML, cybersecurity, and practical automation, with experience in model integration, API orchestration, scalable architecture, and security-minded system design.

πŸ’Ό 20+ Projects
β€’
⚑ 100+ Technologies
β€’
🎯 4+ Years Experience

🧭 My Journey

Victor Muthomi working at a development workstation

Victor Muthomi working at a development workstation

From rural Kenya to the forefront of technology, my journey has been shaped by curiosity, persistence, and a passion for solving real-world problems. My interest in programming began during my teenage years and grew into a career focused on software engineering, where I discovered the satisfaction of building scalable systems that improve how people and organizations work.

Today, I specialize in Python development, backend engineering, and Frappe/ERPNext solutions, designing secure, scalable applications for businesses, institutions, and communities. My experience spans enterprise software, REST APIs, automation, database design, cloud deployments, and AI-powered solutions, enabling me to deliver technology that is both practical and reliable.

As my experience grew, I became increasingly interested in understanding not only how systems are built, but also how they can be brokenβ€”and more importantly, how they can be secured. That curiosity led me into cybersecurity, where I began specializing in offensive security and penetration testing.

I have developed my skills through extensive hands-on practice on platforms including Hack The Box, TryHackMe, PortSwigger Web Security Academy, OWASP Juice Shop, OWASP WebGoat, CyberDefenders, OverTheWire, and PicoCTF. These environments have allowed me to simulate real-world attack scenarios and gain practical experience in reconnaissance, web application security, API security, authentication flaws, privilege escalation, exploitation, post-exploitation, vulnerability assessment, Active Directory fundamentals, Linux and Windows security, and secure coding practices.

My security toolkit includes Burp Suite, Nmap, Wireshark, Metasploit Framework, SQLMap, Nikto, Gobuster, ffuf, Hydra, John the Ripper, Hashcat, Aircrack-ng, Kismet, Impacket, NetExec (formerly CrackMapExec), and custom Python scripts for automation and security testing. Working in Linux-first environments has strengthened my understanding of networking, operating systems, secure system administration, vulnerability assessment, and penetration testing methodologies based on industry best practices.

Today, I combine the perspectives of both a software engineer and an offensive security practitioner. I approach every application with a security-first mindsetβ€”mapping attack surfaces, identifying vulnerabilities, validating security risks responsibly, and translating technical findings into practical remediation strategies. My background as a developer enables me not only to discover security issues but also to understand their root causes and recommend effective, developer-friendly solutions.

I believe the strongest security professionals understand how software is engineered, and the strongest software engineers understand how it can be attacked. My goal is to continue advancing as a penetration tester and security researcher while building resilient applications that can withstand modern cyber threats and contribute to a safer digital ecosystem.

Every line of code I write is a step further from where I began; every security lesson helps make that bridge stronger for the people who depend on it.

Authorized Security Practice

Building software with a tester's mindset.

Check more about my security skills & practice
12+ CVEs Identified
45+ Platforms Tested
28 Critical Hotfixes
99.9% Uptime Secured
ReconnaissanceEnumerationVulnerability AnalysisControlled ExploitationPrivilege Escalation ReviewProfessional Reporting

πŸ† Achievements & Milestones

🌐

Built Production-Ready Web Platforms

Designed and deployed multiple full-stack applications using Python-based frameworks, focusing on reliability, maintainability, and clean architecture. Implemented authentication, APIs, background workers, and database optimisation to support real-world usage.

πŸ’³

Implemented Online Payments Integration (M-Pesa APIs)

Successfully integrated Safaricom Daraja APIs into web systems, enabling secure mobile payments, transaction verification, and automated reconciliation β€” allowing businesses to receive payments directly through their applications with minimal manual intervention.

πŸ€–

Developed Intelligent Automation & AI Solutions

Created AI-assisted tools and chatbot systems capable of handling user queries, data retrieval, and workflow automation. Leveraged NLP models and structured data pipelines to reduce repetitive human tasks and improve response efficiency.

πŸ“Š

Built Data-Driven Decision Systems

Designed data processing pipelines and predictive models that transform raw datasets into actionable insights. Applied statistical analysis and machine learning techniques to support forecasting and business intelligence.

πŸ—οΈ

Engineered ERP & Business Management Solutions

Customized and deployed Frappe/ERPNext systems tailored to organisational workflows, including inventory, invoicing, reporting, and operational tracking. Improved operational visibility and reduced administrative overhead.

βš™οΈ

Created Scalable API Architectures

Designed RESTful services with proper authentication, caching strategies, and background job processing to handle concurrent users and long-running tasks reliably in production environments.

πŸŽ“

Mentored Upcoming Developers

Guided junior developers in programming fundamentals, debugging strategies, and real-world project structure. Helped learners transition from theory to practical software development and professional workflows.

🀝

Delivered Solutions for SMEs and Independent Clients

Worked with businesses and individuals to translate requirements into functional software products. Focused on usability, performance, and long-term maintainability rather than short-term prototypes.

βœ…

Promoted Clean Code & Engineering Best Practices

Adopted modular architecture, version control workflows, documentation standards, and testing strategies to ensure software longevity and team collaboration readiness.

πŸ”

Practiced Responsible Penetration Testing

Conducted authorized security assessments across web applications, APIs, networks, and Linux/Windows environments using structured workflows from reconnaissance through evidence-based reporting.

πŸ§ͺ

Built Hands-On Security Lab Experience

Strengthened offensive and defensive skills through TryHackMe, Hack The Box, OWASP Juice Shop, DVWA, Active Directory practice, vulnerability research, and Python-based security automation.

πŸ•΅οΈ

Mapped Attack Surfaces with OSINT & Recon

Applied reconnaissance workflows using tools such as Shodan, Amass, theHarvester, Maltego, and Nmap to identify exposed assets, service fingerprints, DNS records, and realistic entry points.

πŸ“„

Delivered Clear Security Reports

Produced structured findings with severity, affected assets, reproduction steps, business impact, evidence, remediation guidance, and retest recommendations for technical and leadership audiences.

πŸš€

Continuous Technical Growth Milestone

Progressed from learning programming fundamentals to building complete production systems involving backend services, databases, APIs, automation, and AI β€” demonstrating consistent growth from learner to solution engineer.

🧠

Designed Domain-Aware AI Assistants

Architected intelligent assistants capable of understanding structured organisational knowledge rather than relying solely on generic LLM responses. Implemented retrieval pipelines, contextual memory, and controlled reasoning layers to ensure accurate, explainable, and auditable outputs suitable for real operational environments.

πŸ›‘οΈ

Built Reliable AI Systems for Production Use

Engineered AI workflows beyond experimentation β€” including data validation, model evaluation, fallback logic, and monitoring. Focused on deterministic behaviour, cost control, and graceful degradation, ensuring AI features remain dependable even under uncertain inputs and real user traffic.

πŸ”­

Looking Forward

I focus on applying Artificial Intelligence to solve real-world challenges in developing regions, particularly in healthcare, education, and sustainable agriculture. By combining machine learning, data engineering, and practical software systems, I design solutions that are not only technically advanced but also accessible, reliable, and usable in resource-constrained environments.

My goal is to bridge the gap between modern AI innovation and everyday societal needs β€” transforming data into decision-making tools, automation into empowerment, and technology into opportunity. I believe intelligent systems should augment human capability and deliver measurable impact, regardless of geography or economic standing.